In recent years, the case law of the Court of Justice of the European Union has changed several things that looked settled in GDPR: when compensation is due, what personal data actually is, and how far the right of access reaches. Add to that the guidance of the European Data Protection Board and an increasingly active President of Poland's data protection authority (UODO).

Below we set out what genuinely affects the practice of a Polish controller — with case signatures and dates, so that every point can be checked at source.

Compensation for GDPR infringements — where Article 82 is heading

The most important line of case law in recent years concerns the question that in practice determines the cost of a breach: when does a person whose data has leaked receive compensation?

The starting point is the judgment of 4 May 2023, C-300/21 (Österreichische Post): an infringement of GDPR does not in itself automatically give rise to a right to compensation. The claimant must establish three elements — the infringement, the damage and a causal link between them. At the same time, the Court rejected any threshold of minimum seriousness: non-material damage need not reach a particular level of severity in order to be compensated.

The judgment of 11 April 2024, C-741/21 (juris) clarified how risk is allocated on the controller's side. A controller will not escape liability by pointing out that the infringement was committed by one of its employees — unless it can demonstrate the absence of a causal link. The Court also indicated that the degree of the controller's fault is not a criterion for adjusting the amount of compensation: Article 82 performs a compensatory function, not a punitive one. The President of UODO issued a separate analysis of that judgment in the context of Polish law.

The judgment of 4 September 2025, C-655/23 (Quirin Privatbank) added two points. First, GDPR does not confer on an individual a right to a preventive injunction against a controller where that individual is not seeking erasure of their data — although national law may provide for such a remedy. Second, negative feelings arising from unauthorised disclosure of data fall within the concept of non-material damage, but the injured party must demonstrate both the feelings and their consequences. It is not enough to state that a leak occurred.

The most recent piece of this puzzle is the judgment of 19 March 2026, C-526/24 (Brillen Rottler) — and it is a significant change for every organisation handling data subject requests. The Court held that even a first access request under Article 15 GDPR may be refused as an abuse of rights on the basis of Article 12(5), provided two conditions are met cumulatively: an objective one (despite formal compliance, the purpose of GDPR is not being served) and a subjective one (an intention to obtain an undue advantage). The burden of proof rests on the controller. The Court further indicated that deliberate conduct by an individual aimed at provoking an infringement in order to obtain compensation may break the causal link and rule out a claim under Article 82.

The practical conclusion for a controller: the procedure for handling access requests should provide for a refusal route, with reasons given and the grounds of abuse documented. Until now, most procedures simply had no such route.

What personal data means after EDPS v SRB

The judgment of 4 September 2025, C-413/23 P (EDPS v Single Resolution Board) changes the way we think about pseudonymisation.

The Court adopted a relative understanding of the concept of personal data: pseudonymised data transferred to a recipient that has no means reasonably likely to be used to identify individuals may not constitute personal data for that recipient. The assessment is made from the perspective of the specific recipient, not solely of the controller holding the key.

This is not an invitation to treat pseudonymisation as anonymisation. It is a signal that the status of data depends on the context of the transfer — and that this context must be documented. The EDPB is moving in the same direction: guidelines 01/2025 address pseudonymisation, and in July 2026 guidelines 02/2026 on anonymisation were adopted for consultation, built on a three-part test of the impossibility of singling out a record, of linkability and of inference. The consultation runs until 30 October 2026, so the document is not yet final.

It is worth placing this alongside the judgment of 9 January 2025, C-394/23 (Mousse), in which the Court found that collecting data on a customer's title when buying a rail ticket infringed the minimisation principle. The direction is consistent: what matters is whether a data item is necessary, not whether it is convenient.

Artificial intelligence and automated decisions

Two judgments currently set the compliance framework for decision-making systems.

In case C-634/21 (SCHUFA) of 7 December 2023, the Court held that the automated calculation of a credit score by a credit bureau itself constitutes automated decision-making within the meaning of Article 22(1) GDPR where a third party's decision — a bank's, for instance — depends to a significant degree on that value. Responsibility therefore does not end with whoever signs the decision.

In case C-203/22 (Dun & Bradstreet Austria) of 27 February 2025, the Court explained what the right to "meaningful information about the logic involved" under Article 15(1)(h) means: the controller must describe the procedure and the logic concisely, intelligibly and accessibly, so that the individual can understand which of their data influenced the outcome and how. Trade secrecy does not remove that obligation — the dispute is settled by the supervisory authority or a court, to which the data must be disclosed so that the competing interests can be weighed.

On the soft law side, the most important text is EDPB Opinion 28/2024 of 17 December 2024 on AI models — when a model may be regarded as anonymous, when legitimate interest is the appropriate basis, and what consequences unlawful processing at the training stage has. In July 2026, the EDPB adopted for consultation guidelines 03/2026 on web scraping for generative AI, confirming a basic point: if scraping captures personal data, GDPR applies.

The context for assessing the legal basis remains the judgment of 4 October 2024, C-621/22 (KNLTB), in which the Court confirmed that a purely commercial interest can constitute a legitimate interest within the meaning of Article 6(1)(f) — provided it passes the three-part test of necessity and balancing.

Cookies, consent and legitimate interest — the state of play

A good deal of mythology has grown up in Poland around cookie consent, based on judgments whose content is sometimes cited loosely. It is worth holding on to two reference points.

The first is the CJEU judgment of 1 October 2019 in case C-673/17 (Planet49) — consent expressed through a pre-ticked box is not valid consent. It is a ruling from some years back, but still fundamental, because the practice of pre-ticked consent has not disappeared from Polish websites.

The second is EDPB Opinion 08/2024 of 17 April 2024 on "consent or pay" models on large online platforms. The EDPB indicated that presenting users with a choice solely between consenting to tracking and paying a fee does not, in most cases, make consent freely given.

Separately, it is worth remembering the judgment of 4 October 2024 in case C-621/22 (KNLTB): a purely commercial interest can be a legitimate interest within the meaning of Article 6(1)(f) if it passes the three-part test — identifying the interest, establishing the necessity of the processing and balancing it against individuals' rights. This is an important correction to the practice of supervisory authorities, which had treated a commercial purpose as insufficient by definition.

If the Digital Omnibus enters into force in the proposed form, the rules on access to terminal equipment will move from the ePrivacy Directive into GDPR, and consent will remain the rule — with new exceptions and the option of expressing preferences at browser level. Until then, the current position applies.

The right to erasure — what the EDPB's coordinated action revealed

The right to erasure under Article 17 GDPR was the subject of a coordinated EDPB action in 2025. Thirty-two supervisory authorities took part, 764 organisations were covered and the summary report was published on 18 February 2026.

Seven recurring problems were identified. Three of them are particularly common in Polish practice:

No internal procedure for handling requests. Requests land in a random mailbox, are dealt with ad hoc and nobody tracks the deadlines.

Insufficient information for the individual. The organisation erases data but does not explain the extent of the erasure and what is being retained on another legal basis — and that is the most common source of complaints to the authority.

Apparent anonymisation instead of erasure. Data remains in the system after the identifier has been replaced, yet still allows the person to be identified by linking it with other records. In the light of the draft EDPB guidelines 02/2026 on anonymisation — built on the test of singling out, linkability and inference — such an operation is not anonymisation.

A further coordinated action, launched on 19 March 2026 with 25 authorities taking part, concerns transparency and the information obligations under Articles 12–14 GDPR. The results are being aggregated in the second half of 2026. This is a good moment to review your own privacy notices before the authority does it for you.

The Digital Omnibus — what it will really change and why it has stalled

The simplification package presented by the Commission on 19 November 2025 has, as regards its GDPR strand, still not been adopted — and this is worth stating plainly, because contradictory information is circulating.

A separate act concerning the AI Act was finalised in June 2026. The regulation amending GDPR, however, has stalled in the Council: at the end of June 2026 the Cypriot presidency withdrew its compromise text for want of a qualified majority, and since 1 July 2026 the dossier has been handled by the Irish presidency.

The main proposals concerning GDPR are: amending the definition of personal data towards a relative approach (codifying the judgment in C-413/23 P); new rules on pseudonymised data; allowing legitimate interest as a basis for processing for the development and operation of AI systems; extending the breach notification deadline from 72 to 96 hours while raising the threshold to high-risk breaches; a new ground for refusing an access request in cases of abuse of rights; harmonised EU-wide lists of operations requiring an impact assessment; and moving the cookie rules from the ePrivacy Directive into GDPR.

In their joint opinion of February 2026, the EDPB and the EDPS clearly opposed narrowing the definition of personal data, regarding selective codification of case law as a source of legal uncertainty. They did, however, support extending the breach notification deadline to 96 hours — while calling for it to be harmonised with the shorter deadlines under NIS-2 and DORA.

What this means for a controller today: nothing in your documentation needs to change. It is worth knowing, though, that if the package passes in its current form, your breach notification procedures, your register of operations subject to an impact assessment and your cookie consent mechanics will all need updating.

UODO inspections and fines in 2026

The authority's activity is growing fast. For 2025, UODO recorded 12,986 complaints, against 8,056 the year before, 22,435 notified breaches, 56 organisations inspected and 2,076 decisions. Thirty-two fines were imposed, totalling approximately PLN 64.4 million.

The 2026 sector inspection plan, announced on 8 January 2026, covers five areas: authorities processing data in large-scale EU systems; healthcare providers, as regards CCTV (with particular attention to children's data); public information bulletins, as regards anonymisation and the publication of recordings of municipal council sessions; organisations conducting marketing activities; and online delivery platforms.

The largest of the publicly disclosed 2026 fines was imposed on DPD Polska — PLN 11,461,030 in total (decision of 5 February 2026). It comprised two infringements: the absence of data processing agreements with external carriers, and defectively issued authorisations coupled with a failure to implement adequate organisational measures. It is a reminder that the subcontractor chain is now one of the most closely inspected areas.

Also worth noting is a decision of July 2026 imposing PLN 26,711 on a private individual for domestic CCTV recording image and sound on a public road and on neighbouring properties — the first fine of its kind from the President of UODO.

Polish courts review UODO

2026 has brought a number of rulings showing that the authority's decisions are upheld and set aside in roughly equal measure — and that it is worth knowing both sides of that picture.

Upheld. By judgment of 28 January 2026 (II SA/Wa 890/25), the Provincial Administrative Court in Warsaw dismissed the appeal of the Commander-in-Chief of the Police, confirming a fine of PLN 75,000 for disclosing health and private life data at a press conference; the court held that a press conference is not journalistic activity and that public authorities are not exempt from GDPR. By judgment of 18 March 2026 (II SA/Wa 807/25) the same court upheld a fine of PLN 56,824 imposed on Polskie Radio Szczecin. In June 2026 the Supreme Administrative Court dismissed Virgin Mobile's cassation appeal, upholding a fine of PLN 1,599,395 and confirming that the obligation to test and evaluate the effectiveness of security measures regularly (Article 32(1)(d)) has rested on controllers since 25 May 2018.

Set aside. By judgment of 5 March 2026 (II SA/Wa 837/25), the Provincial Administrative Court set aside the decision imposing a fine of PLN 27 million on Poczta Polska for processing data from the PESEL register for the purposes of the 2020 postal elections, holding that the company had a legal basis in carrying out an instruction of the Prime Minister.

Separately, it is worth noting the Supreme Administrative Court's judgment of 6 February 2026 (III OSK 2014/24) concerning CCTV covering a neighbouring property: the processing was not necessary, since other protective measures were available, so legitimate interest could not serve as a basis.

At EU level, meanwhile, the balance of power between controllers and the EDPB has shifted. In the Grand Chamber judgment of 10 February 2026, C-97/23 P (WhatsApp Ireland), the Court confirmed that binding EDPB decisions issued under Article 65 GDPR may be challenged directly by controllers before the EU courts.

What this means for a Polish controller

Four conclusions that translate into concrete tasks.

Your request-handling procedure must provide for refusal. Following C-526/24, refusing an access request on grounds of abuse of rights is possible even on a first request — but it requires both conditions to be documented, and the burden of proof lies with the controller. A procedure that knows only the "fulfil" route will not let you rely on this.

The status of data must be documented in context. After C-413/23 P, the question "is this personal data?" has no single answer for the whole organisation — the answer depends on who receives it and what they hold. It is worth recording that reasoning each time pseudonymised data is transferred.

Decision-making systems need a description, not just a legal basis. After C-203/22, an individual has the right to understand which of their data influenced the outcome and how. A supplier's trade secrecy does not remove that obligation — which means you must require the information in your contract with the supplier before the system goes into production.

The subcontractor chain is now the most closely inspected area. The PLN 11.46 million fine imposed on DPD Polska for the absence of data processing agreements with carriers and for defective authorisations shows as much. Reviewing your contracts with processors and sub-processors is cheaper than proceedings.

With case law moving this quickly, it is worth basing these decisions on an up-to-date legal analysis of new GDPR case law rather than interpreting each successive judgment on your own.

The consequences of inspections and authority decisions can be seen in specific cases — we describe one of them, concerning CCTV and failure to comply with an order, separately. On who within the organisation should be keeping watch over these obligations, see our article on the role of the DPO.